
Claude Skills by bilal-spotted
github.com/bilal-spottedAI and LLM security CTF recipes. Load for any AI hacking category challenge, prompt injection, jailbreak, MCP tool poisoning, agent tool abuse, provided model files, or AI powered filter bypass.
Cryptographic attack decision tree for CTF crypto. Load for any crypto challenge to identify the primitive (RSA, AES, ECC, DH, hash, PRNG) and select the matching attack. Covers RSA (small e, Wiener, common modulus, Coppersmith, Fermat), AES oracles (ECB, CBC padding, CTR/GCM nonce reuse), ECDSA nonce reuse, LCG/MT state recovery, and hash length extension.
Flag handling and anti-guessing discipline for CTF. Load whenever a candidate flag is produced or a challenge nears solving. Enforces the flag format, forbids guessing or brute-forcing flag text, and defines what counts as a proven solve versus an assumption.
Forensics tool-chain recipes for CTF. Load for any forensics challenge to pick the right recipe by artifact, pcap dissection, memory dumps, disk image carving, Windows artifacts, mobile, timeline analysis, browser, git, containers, steganography, documents.
Binary exploitation playbook for CTF pwn. Load for any pwn challenge to map mitigations to attack techniques: stack overflow, ret2win, ret2libc, ret2csu, ROP, format string, GOT overwrite, one_gadget, and heap techniques (tcache, fastbin, house of force/orange). Includes a pwntools exploit template.
Reverse engineering toolkit and workflow for CTF rev. Load for any rev challenge to pick the right approach by target type (native ELF/PE, .NET, JVM, Python pyc, WASM, packed/obfuscated), find the flag-gating check, and recover the required input, including angr symbolic execution for constraint-heavy binaries.
Web vulnerability attack catalog for CTF. Load when analyzing any web/HTTP challenge to systematically check SQLi, SSTI, SSRF, XXE, IDOR, JWT flaws, prototype pollution, deserialization, path traversal, command injection, open redirect, auth bypass, and race conditions. Provides the fastest confirming test and exploitation path per class.